1 /*
   2  * Copyright (c) 2010, 2013, Oracle and/or its affiliates. All rights reserved.
   3  * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
   4  *
   5  * This code is free software; you can redistribute it and/or modify it
   6  * under the terms of the GNU General Public License version 2 only, as
   7  * published by the Free Software Foundation.  Oracle designates this
   8  * particular file as subject to the "Classpath" exception as provided
   9  * by Oracle in the LICENSE file that accompanied this code.
  10  *
  11  * This code is distributed in the hope that it will be useful, but WITHOUT
  12  * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
  13  * FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
  14  * version 2 for more details (a copy is included in the LICENSE file that
  15  * accompanied this code).
  16  *
  17  * You should have received a copy of the GNU General Public License version
  18  * 2 along with this work; if not, write to the Free Software Foundation,
  19  * Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
  20  *
  21  * Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
  22  * or visit www.oracle.com if you need additional information or have any
  23  * questions.
  24  */
  25 
  26 package jdk.nashorn.api.scripting;
  27 
  28 import static jdk.nashorn.internal.runtime.ECMAErrors.referenceError;
  29 import static jdk.nashorn.internal.runtime.ScriptRuntime.UNDEFINED;
  30 
  31 import java.io.IOException;
  32 import java.io.InputStream;
  33 import java.io.InputStreamReader;
  34 import java.io.Reader;
  35 import java.lang.reflect.Method;
  36 import java.lang.reflect.Modifier;
  37 import java.net.URL;
  38 import java.nio.charset.Charset;
  39 import java.security.AccessControlContext;
  40 import java.security.AccessController;
  41 import java.security.Permissions;
  42 import java.security.PrivilegedAction;
  43 import java.security.PrivilegedActionException;
  44 import java.security.PrivilegedExceptionAction;
  45 import java.security.ProtectionDomain;
  46 import java.text.MessageFormat;
  47 import java.util.Locale;
  48 import java.util.ResourceBundle;
  49 import javax.script.AbstractScriptEngine;
  50 import javax.script.Bindings;
  51 import javax.script.Compilable;
  52 import javax.script.CompiledScript;
  53 import javax.script.Invocable;
  54 import javax.script.ScriptContext;
  55 import javax.script.ScriptEngine;
  56 import javax.script.ScriptEngineFactory;
  57 import javax.script.ScriptException;
  58 import jdk.nashorn.internal.runtime.Context;
  59 import jdk.nashorn.internal.runtime.ErrorManager;
  60 import jdk.nashorn.internal.runtime.GlobalObject;
  61 import jdk.nashorn.internal.runtime.Property;
  62 import jdk.nashorn.internal.runtime.ScriptFunction;
  63 import jdk.nashorn.internal.runtime.ScriptObject;
  64 import jdk.nashorn.internal.runtime.ScriptRuntime;
  65 import jdk.nashorn.internal.runtime.Source;
  66 import jdk.nashorn.internal.runtime.linker.JavaAdapterFactory;
  67 import jdk.nashorn.internal.runtime.options.Options;
  68 
  69 /**
  70  * JSR-223 compliant script engine for Nashorn. Instances are not created directly, but rather returned through
  71  * {@link NashornScriptEngineFactory#getScriptEngine()}. Note that this engine implements the {@link Compilable} and
  72  * {@link Invocable} interfaces, allowing for efficient precompilation and repeated execution of scripts.
  73  * @see NashornScriptEngineFactory
  74  */
  75 
  76 public final class NashornScriptEngine extends AbstractScriptEngine implements Compilable, Invocable {
  77     private static AccessControlContext createPermAccCtxt(final String permName) {
  78         final Permissions perms = new Permissions();
  79         perms.add(new RuntimePermission(permName));
  80         return new AccessControlContext(new ProtectionDomain[] { new ProtectionDomain(null, perms) });
  81     }
  82 
  83     private static final AccessControlContext CREATE_CONTEXT_ACC_CTXT = createPermAccCtxt(Context.NASHORN_CREATE_CONTEXT);
  84     private static final AccessControlContext CREATE_GLOBAL_ACC_CTXT  = createPermAccCtxt(Context.NASHORN_CREATE_GLOBAL);
  85 
  86     private final ScriptEngineFactory factory;
  87     private final Context             nashornContext;
  88     private final ScriptObject        global;
  89     // initialized bit late to be made 'final'. Property object for "context"
  90     // property of global object
  91     private Property                  contextProperty;
  92 
  93     // default options passed to Nashorn Options object
  94     private static final String[] DEFAULT_OPTIONS = new String[] { "-scripting", "-doe" };
  95 
  96     private static final String MESSAGES_RESOURCE = "jdk.nashorn.api.scripting.resources.Messages";
  97 
  98     private static final ResourceBundle MESSAGES_BUNDLE;
  99     static {
 100         MESSAGES_BUNDLE = ResourceBundle.getBundle(MESSAGES_RESOURCE, Locale.getDefault());
 101     }
 102 
 103     private static String getMessage(final String msgId, final String... args) {
 104         try {
 105             return new MessageFormat(MESSAGES_BUNDLE.getString(msgId)).format(args);
 106         } catch (final java.util.MissingResourceException e) {
 107             throw new RuntimeException("no message resource found for message id: "+ msgId);
 108         }
 109     }
 110 
 111     NashornScriptEngine(final NashornScriptEngineFactory factory, final ClassLoader appLoader) {
 112         this(factory, DEFAULT_OPTIONS, appLoader);
 113     }
 114 
 115     NashornScriptEngine(final NashornScriptEngineFactory factory, final String[] args, final ClassLoader appLoader) {
 116         this.factory = factory;
 117         final Options options = new Options("nashorn");
 118         options.process(args);
 119 
 120         // throw ParseException on first error from script
 121         final ErrorManager errMgr = new Context.ThrowErrorManager();
 122         // create new Nashorn Context
 123         this.nashornContext = AccessController.doPrivileged(new PrivilegedAction<Context>() {
 124             @Override
 125             public Context run() {
 126                 try {
 127                     return new Context(options, errMgr, appLoader);
 128                 } catch (final RuntimeException e) {
 129                     if (Context.DEBUG) {
 130                         e.printStackTrace();
 131                     }
 132                     throw e;
 133                 }
 134             }
 135         }, CREATE_CONTEXT_ACC_CTXT);
 136 
 137         // create new global object
 138         this.global = createNashornGlobal();
 139         // set the default engine scope for the default context
 140         context.setBindings(new ScriptObjectMirror(global, global), ScriptContext.ENGINE_SCOPE);
 141 
 142         // evaluate engine initial script
 143         try {
 144             evalEngineScript();
 145         } catch (final ScriptException e) {
 146             if (Context.DEBUG) {
 147                 e.printStackTrace();
 148             }
 149             throw new RuntimeException(e);
 150         }
 151     }
 152 
 153     @Override
 154     public Object eval(final Reader reader, final ScriptContext ctxt) throws ScriptException {
 155         try {
 156             if (reader instanceof URLReader) {
 157                 final URL url = ((URLReader)reader).getURL();
 158                 final Charset cs = ((URLReader)reader).getCharset();
 159                 return evalImpl(compileImpl(new Source(url.toString(), url, cs), ctxt), ctxt);
 160             }
 161             return evalImpl(Source.readFully(reader), ctxt);
 162         } catch (final IOException e) {
 163             throw new ScriptException(e);
 164         }
 165     }
 166 
 167     @Override
 168     public Object eval(final String script, final ScriptContext ctxt) throws ScriptException {
 169         return evalImpl(script.toCharArray(), ctxt);
 170     }
 171 
 172     @Override
 173     public ScriptEngineFactory getFactory() {
 174         return factory;
 175     }
 176 
 177     @Override
 178     public Bindings createBindings() {
 179         final ScriptObject newGlobal = createNashornGlobal();
 180         return new ScriptObjectMirror(newGlobal, newGlobal);
 181     }
 182 
 183     // Compilable methods
 184 
 185     @Override
 186     public CompiledScript compile(final Reader reader) throws ScriptException {
 187         try {
 188             return asCompiledScript(compileImpl(Source.readFully(reader), context));
 189         } catch (final IOException e) {
 190             throw new ScriptException(e);
 191         }
 192     }
 193 
 194     @Override
 195     public CompiledScript compile(final String str) throws ScriptException {
 196         return asCompiledScript(compileImpl(str.toCharArray(), context));
 197     }
 198 
 199     // Invocable methods
 200 
 201     @Override
 202     public Object invokeFunction(final String name, final Object... args)
 203             throws ScriptException, NoSuchMethodException {
 204         return invokeImpl(null, name, args);
 205     }
 206 
 207     @Override
 208     public Object invokeMethod(final Object thiz, final String name, final Object... args)
 209             throws ScriptException, NoSuchMethodException {
 210         if (thiz == null) {
 211             throw new IllegalArgumentException(getMessage("thiz.cannot.be.null"));
 212         }
 213         return invokeImpl(thiz, name, args);
 214     }
 215 
 216     private <T> T getInterfaceInner(final Object thiz, final Class<T> clazz) {
 217         if (clazz == null || !clazz.isInterface()) {
 218             throw new IllegalArgumentException(getMessage("interface.class.expected"));
 219         }
 220 
 221         // perform security access check as early as possible
 222         final SecurityManager sm = System.getSecurityManager();
 223         if (sm != null) {
 224             if (! Modifier.isPublic(clazz.getModifiers())) {
 225                 throw new SecurityException(getMessage("implementing.non.public.interface", clazz.getName()));
 226             }
 227             Context.checkPackageAccess(clazz.getName());
 228         }
 229 
 230         ScriptObject realSelf = null;
 231         ScriptObject realGlobal = null;
 232         if(thiz == null) {
 233             // making interface out of global functions
 234             realSelf = realGlobal = getNashornGlobalFrom(context);
 235         } else if (thiz instanceof ScriptObjectMirror) {
 236             final ScriptObjectMirror mirror = (ScriptObjectMirror)thiz;
 237             realSelf = mirror.getScriptObject();
 238             realGlobal = mirror.getHomeGlobal();
 239             if (! realGlobal.isOfContext(nashornContext)) {
 240                 throw new IllegalArgumentException(getMessage("script.object.from.another.engine"));
 241             }
 242         } else if (thiz instanceof ScriptObject) {
 243             // called from script code.
 244             realSelf = (ScriptObject)thiz;
 245             realGlobal = Context.getGlobal();
 246             if (realGlobal == null) {
 247                 throw new IllegalArgumentException(getMessage("no.current.nashorn.global"));
 248             }
 249 
 250             if (! realGlobal.isOfContext(nashornContext)) {
 251                 throw new IllegalArgumentException(getMessage("script.object.from.another.engine"));
 252             }
 253         }
 254 
 255         if (realSelf == null) {
 256             throw new IllegalArgumentException(getMessage("interface.on.non.script.object"));
 257         }
 258 
 259         try {
 260             final ScriptObject oldGlobal = Context.getGlobal();
 261             final boolean globalChanged = (oldGlobal != realGlobal);
 262             try {
 263                 if (globalChanged) {
 264                     Context.setGlobal(realGlobal);
 265                 }
 266 
 267                 if (! isInterfaceImplemented(clazz, realSelf)) {
 268                     return null;
 269                 }
 270                 return clazz.cast(JavaAdapterFactory.getConstructor(realSelf.getClass(), clazz).invoke(realSelf));
 271             } finally {
 272                 if (globalChanged) {
 273                     Context.setGlobal(oldGlobal);
 274                 }
 275             }
 276         } catch(final RuntimeException|Error e) {
 277             throw e;
 278         } catch(final Throwable t) {
 279             throw new RuntimeException(t);
 280         }
 281     }
 282 
 283     @Override
 284     public <T> T getInterface(final Class<T> clazz) {
 285         return getInterfaceInner(null, clazz);
 286     }
 287 
 288     @Override
 289     public <T> T getInterface(final Object thiz, final Class<T> clazz) {
 290         if (thiz == null) {
 291             throw new IllegalArgumentException(getMessage("thiz.cannot.be.null"));
 292         }
 293         return getInterfaceInner(thiz, clazz);
 294     }
 295 
 296     // These are called from the "engine.js" script
 297 
 298     /**
 299      * This hook is used to search js global variables exposed from Java code.
 300      *
 301      * @param self 'this' passed from the script
 302      * @param ctxt current ScriptContext in which name is searched
 303      * @param name name of the variable searched
 304      * @return the value of the named variable
 305      */
 306     public Object __noSuchProperty__(final Object self, final ScriptContext ctxt, final String name) {
 307         final int scope = ctxt.getAttributesScope(name);
 308         final ScriptObject ctxtGlobal = getNashornGlobalFrom(ctxt);
 309         if (scope != -1) {
 310             return ScriptObjectMirror.unwrap(ctxt.getAttribute(name, scope), ctxtGlobal);
 311         }
 312 
 313         if (self == UNDEFINED) {
 314             // scope access and so throw ReferenceError
 315             throw referenceError(ctxtGlobal, "not.defined", name);
 316         }
 317 
 318         return UNDEFINED;
 319     }
 320 
 321     private ScriptObject getNashornGlobalFrom(final ScriptContext ctxt) {
 322         final Bindings bindings = ctxt.getBindings(ScriptContext.ENGINE_SCOPE);
 323         if (bindings instanceof ScriptObjectMirror) {
 324              ScriptObject sobj = ((ScriptObjectMirror)bindings).getScriptObject();
 325              if (sobj instanceof GlobalObject) {
 326                  return sobj;
 327              }
 328         }
 329 
 330         // didn't find global object from context given - return the engine-wide global
 331         return global;
 332     }
 333 
 334     private ScriptObject createNashornGlobal() {
 335         final ScriptObject newGlobal = AccessController.doPrivileged(new PrivilegedAction<ScriptObject>() {
 336             @Override
 337             public ScriptObject run() {
 338                 try {
 339                     return nashornContext.newGlobal();
 340                 } catch (final RuntimeException e) {
 341                     if (Context.DEBUG) {
 342                         e.printStackTrace();
 343                     }
 344                     throw e;
 345                 }
 346             }
 347         }, CREATE_GLOBAL_ACC_CTXT);
 348 
 349         nashornContext.initGlobal(newGlobal);
 350 
 351         final int NON_ENUMERABLE_CONSTANT = Property.NOT_ENUMERABLE | Property.NOT_CONFIGURABLE | Property.NOT_WRITABLE;
 352         // current ScriptContext exposed as "context"
 353         // "context" is non-writable from script - but script engine still
 354         // needs to set it and so save the context Property object
 355         contextProperty = newGlobal.addOwnProperty("context", NON_ENUMERABLE_CONSTANT, UNDEFINED);
 356         // current ScriptEngine instance exposed as "engine". We added @SuppressWarnings("LeakingThisInConstructor") as
 357         // NetBeans identifies this assignment as such a leak - this is a false positive as we're setting this property
 358         // in the Global of a Context we just created - both the Context and the Global were just created and can not be
 359         // seen from another thread outside of this constructor.
 360         newGlobal.addOwnProperty("engine", NON_ENUMERABLE_CONSTANT, this);
 361         // global script arguments with undefined value
 362         newGlobal.addOwnProperty("arguments", Property.NOT_ENUMERABLE, UNDEFINED);
 363         // file name default is null
 364         newGlobal.addOwnProperty(ScriptEngine.FILENAME, Property.NOT_ENUMERABLE, null);
 365         return newGlobal;
 366     }
 367 
 368     private void evalEngineScript() throws ScriptException {
 369         final String script = "resources/engine.js";
 370         final String name   = NashornException.ENGINE_SCRIPT_SOURCE_NAME;
 371         try {
 372             final InputStream is = AccessController.doPrivileged(
 373                     new PrivilegedExceptionAction<InputStream>() {
 374                         @Override
 375                         public InputStream run() throws Exception {
 376                             final URL url = NashornScriptEngine.class.getResource(script);
 377                             return url.openStream();
 378                         }
 379                     });
 380             put(ScriptEngine.FILENAME, name);
 381             try (final InputStreamReader isr = new InputStreamReader(is)) {
 382                 eval(isr);
 383             }
 384         } catch (final PrivilegedActionException | IOException e) {
 385             if (Context.DEBUG) {
 386                 e.printStackTrace();
 387             }
 388             throw new ScriptException(e);
 389         } finally {
 390             put(ScriptEngine.FILENAME, null);
 391         }
 392     }
 393 
 394     // scripts should see "context" and "engine" as variables
 395     private void setContextVariables(final ScriptContext ctxt) {
 396         final ScriptObject ctxtGlobal = getNashornGlobalFrom(ctxt);
 397         // set "context" global variable via contextProperty - because this
 398         // property is non-writable
 399         contextProperty.setObjectValue(ctxtGlobal, ctxtGlobal, ctxt, false);
 400         Object args = ScriptObjectMirror.unwrap(ctxt.getAttribute("arguments"), ctxtGlobal);
 401         if (args == null || args == UNDEFINED) {
 402             args = ScriptRuntime.EMPTY_ARRAY;
 403         }
 404         // if no arguments passed, expose it
 405         args = ((GlobalObject)ctxtGlobal).wrapAsObject(args);
 406         ctxtGlobal.set("arguments", args, false);
 407     }
 408 
 409     private Object invokeImpl(final Object selfObject, final String name, final Object... args) throws ScriptException, NoSuchMethodException {
 410         name.getClass(); // null check
 411 
 412         ScriptObjectMirror selfMirror = null;
 413         if (selfObject instanceof ScriptObjectMirror) {
 414             selfMirror = (ScriptObjectMirror)selfObject;
 415             if (! selfMirror.getHomeGlobal().isOfContext(nashornContext)) {
 416                 throw new IllegalArgumentException(getMessage("script.object.from.another.engine"));
 417             }
 418         } else if (selfObject instanceof ScriptObject) {
 419             // invokeMethod called from script code - in which case we may get 'naked' ScriptObject
 420             // Wrap it with oldGlobal to make a ScriptObjectMirror for the same.
 421             final ScriptObject oldGlobal = Context.getGlobal();
 422             if (oldGlobal == null) {
 423                 throw new IllegalArgumentException(getMessage("no.current.nashorn.global"));
 424             }
 425 
 426             if (! oldGlobal.isOfContext(nashornContext)) {
 427                 throw new IllegalArgumentException(getMessage("script.object.from.another.engine"));
 428             }
 429 
 430             selfMirror = (ScriptObjectMirror)ScriptObjectMirror.wrap(selfObject, oldGlobal);
 431         } else if (selfObject == null) {
 432             // selfObject is null => global function call
 433             final ScriptObject ctxtGlobal = getNashornGlobalFrom(context);
 434             selfMirror = (ScriptObjectMirror)ScriptObjectMirror.wrap(ctxtGlobal, ctxtGlobal);
 435         }
 436 
 437         if (selfMirror != null) {
 438             try {
 439                 return ScriptObjectMirror.translateUndefined(selfMirror.call(name, args));
 440             } catch (final Exception e) {
 441                 final Throwable cause = e.getCause();
 442                 if (cause instanceof NoSuchMethodException) {
 443                     throw (NoSuchMethodException)cause;
 444                 }
 445                 throwAsScriptException(e);
 446                 throw new AssertionError("should not reach here");
 447             }
 448         }
 449 
 450         // Non-script object passed as selfObject
 451         throw new IllegalArgumentException(getMessage("interface.on.non.script.object"));
 452     }
 453 
 454     private Object evalImpl(final char[] buf, final ScriptContext ctxt) throws ScriptException {
 455         return evalImpl(compileImpl(buf, ctxt), ctxt);
 456     }
 457 
 458     private Object evalImpl(final ScriptFunction script, final ScriptContext ctxt) throws ScriptException {
 459         if (script == null) {
 460             return null;
 461         }
 462         final ScriptObject oldGlobal = Context.getGlobal();
 463         final ScriptObject ctxtGlobal = getNashornGlobalFrom(ctxt);
 464         final boolean globalChanged = (oldGlobal != ctxtGlobal);
 465         try {
 466             if (globalChanged) {
 467                 Context.setGlobal(ctxtGlobal);
 468             }
 469 
 470             setContextVariables(ctxt);
 471             return ScriptObjectMirror.translateUndefined(ScriptObjectMirror.wrap(ScriptRuntime.apply(script, ctxtGlobal), ctxtGlobal));
 472         } catch (final Exception e) {
 473             throwAsScriptException(e);
 474             throw new AssertionError("should not reach here");
 475         } finally {
 476             if (globalChanged) {
 477                 Context.setGlobal(oldGlobal);
 478             }
 479         }
 480     }
 481 
 482     private static void throwAsScriptException(final Exception e) throws ScriptException {
 483         if (e instanceof ScriptException) {
 484             throw (ScriptException)e;
 485         } else if (e instanceof NashornException) {
 486             final NashornException ne = (NashornException)e;
 487             final ScriptException se = new ScriptException(
 488                 ne.getMessage(), ne.getFileName(),
 489                 ne.getLineNumber(), ne.getColumnNumber());
 490             se.initCause(e);
 491             throw se;
 492         } else if (e instanceof RuntimeException) {
 493             throw (RuntimeException)e;
 494         } else {
 495             // wrap any other exception as ScriptException
 496             throw new ScriptException(e);
 497         }
 498     }
 499 
 500     private CompiledScript asCompiledScript(final ScriptFunction script) {
 501         return new CompiledScript() {
 502             @Override
 503             public Object eval(final ScriptContext ctxt) throws ScriptException {
 504                 return evalImpl(script, ctxt);
 505             }
 506             @Override
 507             public ScriptEngine getEngine() {
 508                 return NashornScriptEngine.this;
 509             }
 510         };
 511     }
 512 
 513     private ScriptFunction compileImpl(final char[] buf, final ScriptContext ctxt) throws ScriptException {
 514         final Object val = ctxt.getAttribute(ScriptEngine.FILENAME);
 515         final String fileName = (val != null) ? val.toString() : "<eval>";
 516         return compileImpl(new Source(fileName, buf), ctxt);
 517     }
 518 
 519     private ScriptFunction compileImpl(final Source source, final ScriptContext ctxt) throws ScriptException {
 520         final ScriptObject oldGlobal = Context.getGlobal();
 521         final ScriptObject ctxtGlobal = getNashornGlobalFrom(ctxt);
 522         final boolean globalChanged = (oldGlobal != ctxtGlobal);
 523         try {
 524             if (globalChanged) {
 525                 Context.setGlobal(ctxtGlobal);
 526             }
 527 
 528             return nashornContext.compileScript(source, ctxtGlobal);
 529         } catch (final Exception e) {
 530             throwAsScriptException(e);
 531             throw new AssertionError("should not reach here");
 532         } finally {
 533             if (globalChanged) {
 534                 Context.setGlobal(oldGlobal);
 535             }
 536         }
 537     }
 538 
 539     private static boolean isInterfaceImplemented(final Class<?> iface, final ScriptObject sobj) {
 540         for (final Method method : iface.getMethods()) {
 541             // ignore methods of java.lang.Object class
 542             if (method.getDeclaringClass() == Object.class) {
 543                 continue;
 544             }
 545 
 546             Object obj = sobj.get(method.getName());
 547             if (! (obj instanceof ScriptFunction)) {
 548                 return false;
 549             }
 550         }
 551         return true;
 552     }
 553 }